积极预防 及时发现
快速响应 力保恢复
Imp Webmail 2.2.6及其早期版本中的status.php3中的Cross-site s...
发布时间:2001-12-06 信息来源:管理员

CNCVE编号:CNCVE-20010857 CVE编号:CAN-2001-0857 安全级别:中 漏洞中文描述: Imp Webmail 2.2.6及其早期版本中的status.php3中的Cross-site scripting漏洞允许远程攻击者通过message参数来劫持会话cookies来访问其他用户的电子邮件。 漏洞英文描述: Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter. 漏洞参考: Reference: BUGTRAQ:20011109 Imp Webmail session hijacking vulnerability Reference: URL:http://marc.theaimsgroup.com/?l=bugtraq&m=100535679608486&w=2 Reference: BUGTRAQ:20011110 IMP 2.2.7 (SECURITY) released Reference: URL:http://marc.theaimsgroup.c 系统类型:其他 漏洞类型:异常处理错误